On Wed, 24 Oct 2007, Henning Brauer wrote:Virtualization provides near absolute security - DOM0 is not visible to the user at all, only passing network traffic and handling kernel calls. The security comes about in that each DOMU is totally isolated from the the others, while the core DOM0 is isolated from any attacks. There is also a big benefit when maintaing VM images - restoring a VM in the case of corruption/attach/whatever is as simple as reloading a copy of that image and connecting to system data on the local SAN. Irrespective of the guest OS, there is good security between the virtualized machines. Running OBSD as the guest OS provides the best of both worlds, and it would be great if OBSD would run paravirtualized for the best performance, but apparently nobody has a need for that functionality. Nobpdy has to write any code to understand that - the secuity benefits are ovbious to everyone from the PHBs to the admins. Of course, this is most obvious in 'enterprise space', which is pretty far removed from the typical OBSD world. Lee ================================================ Leland V. Lammert lvl@omnitec.net Chief Scientist Omnitec Corporation Network/Internet Consultants www.omnitec.net ================================================
| Eric Sandeen | [PATCH 0/4] (RESEND) ext3[34] barrier changes |
| Jeremy Fitzhardinge | [PATCH 02 of 36] x86: add memory clobber to save/loadsegment |
| Linus Torvalds | Linux 2.6.25-rc2 |
| Andrew Morton | Re: 2.6.21-rc2-mm1 |
git: | |
| Linus Torvalds | Re: VCS comparison table |
| Joakim Tjernlund | git-svn set-tree bug |
| Avery Pennarun | Re: why is git destructive by default? (i suggest it not be!) |
| Karl | Re: People unaware of the importance of "git gc"? |
| Richard Stallman | Real men don't attack straw men |
| Benoit Chesneau | problem sata with asus m2v-mx motherboard |
| James Hartley | scp batch mode? |
| Brandon Lee | DELL PERC 5iR slow performance |
| Framstag | ftp-error: bind: Address already in use? |
| Dave `geek' Gymer | WARNING (was Re: New afio release) |
| Theodore Ts'o | RESULT: comp.os.linux passes: 858: 5 |
| Ian Kluft | RESULT: comp.os.linux reorganization, all groups pass (part 3/3) |
| problem downloading linux-staging tree | 1 hour ago | Linux general |
| ptrace and big kernel lock | 2 hours ago | Linux kernel |
| SMDK2410 LCD Framebuffer driver | 7 hours ago | Linux kernel |
| Resetting the bios password for Toshiba Laptop | 8 hours ago | Hardware |
| Problem booting a barebone kernel in VMWare | 11 hours ago | Linux kernel |
| IP layer send packet | 15 hours ago | Linux kernel |
| PID to ELF image full path | 17 hours ago | Linux kernel |
| types of kernel | 1 day ago | Linux kernel |
| magical mounts | 3 days ago | Linux kernel |
| Problem in scim in Fedora 9 | 3 days ago | Linux general |
